EDBT 2026 Demo / reviewers in the wild / expert
Tao Wang 0012
dblp:12/5838-12
· DBLP profile ↗
18ranked-venue papers
6as first author
10since 2021 · last 2026
0000-0003-3886-0420ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 17 · 6 first-author · 9 since 2021Computer networks · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | WFCAT: Augmenting Website Fingerprinting With Channel-Wise Attention on Timing FeaturesabstractWebsite Fingerprinting (WF) aims to deanonymize users on the Tor network by analyzing encrypted network traffic. Recent deep-learning-based attacks show high accuracy on undefended traces. However, they struggle against modern defenses that use tactics like injecting dummy packets and delaying real packets, which significantly degrade classification performance. Our analysis reveals that current attacks inadequately leverage the timing information inherent in traffic traces, which persists as a source of leakage even under robust defenses. Addressing this shortfall, we introduce a novel feature representation named the Inter-Arrival Time (IAT) histogram, which quantifies the frequencies of packet inter-arrival times across predetermined time slots. Complementing this feature, we propose a new CNN-based attack, WFCAT, enhanced with two architectural blocks designed to effectively extract and utilize timing information. The model employs convolutional kernels of varying sizes to capture multi-scale temporal features, which are then integrated through a weighted combination across feature channels. This channel-wise attention mechanism enables the model to adaptively emphasize informative patterns while suppressing noise, thereby improving its robustness against timing obfuscation. Our experiments validate that WFCAT substantially outperforms existing methods on defended traces in both closed- and open-world scenarios. Notably, WFCAT achieves over 59% accuracy against Surakav, a recently developed robust defense, marking an improvement of over 28% and 48% against the state-of-the-art attacks RF and Tik-Tok, respectively, in the closed-world scenario. Jiajun Gong, Siyuan Liang 0004, Tao Wang 0012, Ee-Chien Chang |
IEEE Trans. Dependable Secur. Comput. | 5 |
| 2026 | TrapFlow: Controllable Website Fingerprinting Defense via Dynamic Backdoor LearningabstractWebsite fingerprinting (WF) attacks, which covertly monitor user communications to identify the web pages they visit, pose a serious threat to user privacy. Existing WF defenses attempt to reduce attack accuracy by disrupting traffic patterns, but attackers can retrain their models to adapt, making these defenses ineffective. Meanwhile, their high overhead limits deployability. To overcome these limitations, we introduce a novel controllable website fingerprinting defense called TrapFlow based on backdoor learning. TrapFlow exploits the tendency of neural networks to memorize subtle patterns by injecting crafted trigger sequences into targeted website traffic, causing the attacker’s model to build incorrect associations during training. If the attacker attempts to adapt by training on such noisy data, TrapFlow ensures that the model internalizes the trigger as a dominant feature, leading to widespread misclassification across unrelated websites. Conversely, if the attacker ignores these patterns and trains only on clean data, the trigger behaves as an adversarial patch at inference time, causing model misclassification. To achieve this dual effect, we optimize the trigger using the Fast Levenshtein-like distance to maximize both its learnability and distinctiveness from normal traffic. Experiments show that TrapFlow significantly reduces the accuracy of the RF attack from 99% to 6% with 74% data overhead. This compares favorably against two SOTA defenses: FRONT reduces accuracy by only 2% at a similar overhead, while Palette achieves 32% accuracy, but with 48% more overhead. We further validate the practicality of our method in a real Tor network environment. Siyuan Liang 0004, Jiajun Gong, Tianmeng Fang, Aishan Liu, Tao Wang 0012, Xiaochun Cao, Dacheng Tao, Ee-Chien Chang |
IEEE Trans. Inf. Forensics Secur. | 5 |
| 2025 | FOADA: Toward Robust Open-World Mobile App FingerprintingabstractSmartphone users are susceptible to a privacy leakage attack called App Fingerprinting (AF), where traffic analysis is used to infer the apps in use. Despite packet encryption, AF attacks leverage packet size and timing information to identify apps, posing a privacy threat. However, existing attacks fail when a few apps are used concurrently, causing unsegmented traffic with app multiplexing and overlapping. The key reason is that they cannot accurately identify active time boundaries for the apps. This paper presents a novel AF attack, FOADA, the first to accurately predict both the location and label of a target app in traffic. FOADA approaches AF as an object detection problem, training a deep learning model to estimate boundary positions and classify traffic segments. Accurate boundary predictions help the model focus on the most relevant traffic segment, enhancing its classification performance. FOADA excels in handling noisy app traffic. With app multiplexing, it achieves an F1-score of 0.96 for predicting only app labels and an F1-score of 0.92 for predicting both app labels and their locations. FOADA surpasses the state-of-the-art attack PacketPrint, which achieves F1-scores of 0.80 and 0.48 in these two scenarios, respectively. The inference time of FOADA is 2,000 times faster than PacketPrint. Jiajun Gong, Guotao Meng, Siyuan Liang 0004, Tao Wang 0012, Ee-Chien Chang |
IEEE Trans. Inf. Forensics Secur. | 5 |
| 2024 | WFDefProxy: Real World Implementation and Evaluation of Website Fingerprinting DefensesabstractTor, an onion-routing anonymity network, can be attacked by Website Fingerprinting (WF), which de-anonymizes encrypted web browsing traffic by analyzing its unique sequence characteristics. Although many defenses have been proposed, few have been implemented and tested in the real world; most state-of-the-art defenses were only simulated. Simulations fail to capture the real performance of these defenses as they make simplifying assumptions about the protocol stack and network conditions. To allow WF defenses to be analyzed as real implementations, we create WFDefProxy, the first general platform for WF defense implementation on Tor as pluggable transports. We implement three state-of-the-art WF defenses: FRONT, Tamaraw, and RegulaTor. We evaluate each defense extensively by directly collecting defended datasets under WFDefProxy. Our results show that simulation can be inaccurate in many cases. Specifically, Tamaraw’s time overhead was underestimated by 22% in one setting and overestimated by 24% in another. RegulaTor’s time overhead was underestimated by 30–40%. We find that a major source of simulation inaccuracy is that they cannot incorporate how packets depend on each other. We also find that adverse network conditions (which are ignored in simulation), especially congestion, can affect the evaluated overhead of defenses. These results show that it is important to evaluate defenses as implementations instead of only simulations to avoid errors in evaluation. Jiajun Gong, Wuqi Zhang, Charles Zhang 0001, Tao Wang 0012 |
IEEE Trans. Inf. Forensics Secur. | 4 |
| 2024 | RUDOLF: An Efficient and Adaptive Defense Approach Against Website Fingerprinting Attacks Based on Soft Actor-Critic AlgorithmabstractAlthough Tor is designed to provide anonymity, website fingerprinting (WF) attacks have posed significant threats to user privacy. In response, various defense approaches have been developed. Randomization and regularization-based defenses are criticized to be inefficient due to their bandwidth-consuming nature. Some adversarial learning-based defenses are impractical because the generation of perturbation depends on the complete traffic traces. Other adversarial learning-based defenses have weaknesses of lacking adaptability because their perturbations are input-agnostic. To overcome these shortcomings, we propose RUDOLF, an efficient and adaptive WF defense based on the soft actor-critic (SAC) algorithm of reinforcement learning (RL). We train the agent that can incrementally output perturbations synchronously following each burst of real-time traffic. Different from previous defenses, RUDOLF’s perturbation does not depend on the integrity of the traffic and concerns the actual real-time traffic, which ensures the practicality of implementation and adaptability. Besides, we take advantage of the exploratory characteristics of the SAC algorithm to obtain the optimal policy of adding perturbations that can efficiently balance defense effects and bandwidth consumption. Experiments on synthetic datasets show that with less than 30% bandwidth overhead (BWO), RUDOLF can reduce the average attack accuracy to around 15%–20%, which is superior to previous works. We also have implemented RUDOLF as a Tor pluggable transport. The performance in the real Tor network shows that RUDOLF can reduce the average accuracy of WF classifier to around 24% with about 25% BWO and almost no time delay. Meiyi Jiang, Baojiang Cui, Junsong Fu 0001, Tao Wang 0012, Bharat K. Bhargava |
IEEE Trans. Inf. Forensics Secur. | 4 |
| 2024 | KimeraPAD: A Novel Low-Overhead Real-Time Defense Against Website Fingerprinting Attacks Based on Deep Reinforcement LearningabstractThe onion router (Tor) is a network system for anonymous communication. However, website fingerprinting (WF) attacks have threatened the anonymity of Tor. WF attackers can passively monitor and collect traffic, classify the victims’ traffic based on machine learning or deep learning, and identify the websites the victims visit. In recent years, there has been some research on WF defense, but most of the works have high bandwidth and latency overhead. Besides, some defenses are criticized as being unrealistic to implement in real-time due to the need for prior knowledge of the traffic’s exact packet sequences, and the lengths of sequences. In this paper, we propose KimeraPAD, a defense against WF attacks based on deep reinforcement learning. Specifically, our method first trains an agent to generate perturbations confusing the attacker’s classifier. To overcome the weak point of WF defense based on adversarial learning, we then design the implementation method and incur randomness so that it can inject dummy packets in real time and resist adversarial training. Experimental results demonstrate that our method can greatly reduce attack accuracy with a low bandwidth overhead. Besides, KimeraPAD can also be implemented on the client side, which simplifies the implementation a lot while achieving excellent performance. Meiyi Jiang, Baojiang Cui, Junsong Fu 0001, Tao Wang 0012 |
IEEE Trans. Netw. Serv. Manag. | 4 |
| 2022 | Exposing the Rat in the Tunnel: Using Traffic Analysis for Tor-based Malware DetectionabstractTor~\citetor is the most widely used anonymous communication network with millions of daily users~\citetormetrics. Since Tor provides server and client anonymity, hundreds of malware binaries found in the wild rely on it to hide their presence and hinder Command & Control (C&C) takedown operations. We believe Tor is a paramount tool enabling online freedom and privacy, and blocking it to defend against such malware is infeasible for both users and organizations. In this work, we present effective traffic analysis approaches that can accurately identify Tor-based malware communication. We collect hundreds of Tor-based malware binaries, execute and examine more than 47,000 active encrypted malware connections and compare them with benign browsing traffic. In addition to traditional traffic analysis features (which work at the connection level), we propose global host-level network features to capture peculiar malware communication fingerprints across host logs. Our experiments confirm that our models are able to detect "zero-day'' malware connections with 0.7% FPR even when malware connections constitute less than 5% of Tor traces in the test set. Using multi-labeling approaches, we are able to accurately detect the malware behavior-based classes (grayware, ransomware, etc). Finally, we evaluate the robustness of our models on real-world enterprise logs and show that the classifiers can identify infected hosts even with missing features. Priyanka Dodia, Mashael Al Sabah, Omar Alrawi, Tao Wang 0012 |
CCS | 4 |
| 2022 | Surakav: Generating Realistic Traces for a Strong Website Fingerprinting DefenseabstractWebsite Fingerprinting (WF) attacks utilize size and timing information of encrypted network traffic to infer the user’s browsing activity, posing a great threat to privacy-enhancing technologies like Tor; nevertheless, Tor has not adopted any defense because existing defenses are not convincing enough to show their effectiveness. Some defenses have been overcome by newer attacks; other defenses are never implemented and tested in the real open-world scenario.In this paper, we propose Surakav, a tunable and practical defense that is effective against WF attacks with reasonable overhead. Surakav makes use of a Generative Adversarial Network (GAN) to generate realistic sending patterns and regulates buffered data according to the sampled patterns. We implement Surakav and evaluate it on the live Tor network. Experiments show that Surakav is able to reduce the attacker’s true positive rate by 57% with 55% data overhead and 16% time overhead, saving 42% data overhead compared to FRONT. In the heavyweight setting, Surakav outperforms the strongest known defense, Tamaraw, requiring 50% less overhead in data and time to lower the attacker’s true positive rate to only 8%. We also show that two existing defenses, Walkie-Talkie and TrafficSliver, can be fortified with our GAN-based trace generator. Jiajun Gong, Wuqi Zhang, Charles Zhang 0001, Tao Wang 0012 |
SP | 4 |
| 2022 | An Automated Multi-Tab Website Fingerprinting AttackabstractIn Website Fingerprinting (WF) attack, a local passive eavesdropper utilizes network flow information to identify which web pages a user is browsing. Previous researchers have demonstrated the feasibility and effectiveness of WF attacks under a strong Single Page Assumption: the network flow extracted by the adversary belongs to a single web page. In reality, the assumption may not hold because users tend to open multiple tabs simultaneously (or within a short period of time) so that their network traffic is mixed. In this article, we propose an automated multi-tab Website Fingerprinting attack that is able to accurately classify websites regardless of the number of simultaneously opened pages. Our design is powered by two innovative designs. First, we develop a split point classification method to dynamically identify the split point between the first page and its subsequent pages. As a result, the network traffic before the split point is solely generated for the first page. Then, we propose a new chunk-based WF classifier to infer the websites based on the initial chunk of clean traffic. For both classifiers, we apply automated feature selection to select a concise yet representative feature set. We implement a prototype of our design and perform extensive evaluations using SSH and Tor-based datasets to demonstrate the effectiveness of both our system components individually and the integrated system as a whole. Qilei Yin, Zhuotao Liu, Qi Li 0002, Tao Wang 0012, Qian Wang 0002, Chao Shen 0001, Yixiao Xu |
IEEE Trans. Dependable Secur. Comput. | 4 |
| 2021 | The One-Page Setting: A Higher Standard for Evaluating Website Fingerprinting DefensesabstractTo defeat Website Fingerprinting (WF) attacks that threaten privacy on anonymity technologies such as Tor, defenses have been proposed and evaluated under the multi-page setting. The multi-page setting was designed as a difficult setting for the attacker and therefore gives too much of an advantage to the defense, allowing weak defenses to show success. We argue that all WF defenses should instead be evaluated under the one-page setting so that the defender needs to meet a higher standard of success. Tao Wang 0012 |
CCS | 1 |
| 2020 | Designing a Better Browser for Tor with BLAST
Tao Wang 0012 |
NDSS | 1 |
| 2020 | High Precision Open-World Website FingerprintingabstractTraffic analysis attacks to identify which web page a client is browsing, using only her packet metadata - known as website fingerprinting (WF) - has been proven effective in closed-world experiments against privacy technologies like Tor. We want to investigate their usefulness in the real open world. Several WF attacks claim to have high recall and low false positive rate, but they have only been shown to succeed against high base rate pages. We explicitly incorporate the base rate into precision and call it r-precision. Using this metric, we show that the best previous attacks have poor precision when the base rate is realistically low; we study such a scenario (r = 1000), where the maximum r-precision achieved was only 0.14.To improve r-precision, we propose three novel classes of precision optimizers that can be applied to any classifier to increase precision. For r = 1000, our best optimized classifier can achieve a precision of at least 0.86, representing a precision increase by more than 6 times. For the first time, we show a WF classifier that can scale to any open world set size. We also investigate the use of precise classifiers to tackle realistic objectives in website fingerprinting, including different types of websites, identification of sensitive clients, and defeating website fingerprinting defenses. Tao Wang 0012 |
SP | 1 |
| 2020 | Zero-delay Lightweight Defenses against Website Fingerprinting
Jiajun Gong, Tao Wang 0012 |
USENIX Security Symposium | 2 |
| 2018 | A Multi-tab Website Fingerprinting AttackabstractIn a Website Fingerprinting (WF) attack, a local, passive eavesdropper utilizes network flow information to identify which web pages a user is browsing. Previous researchers have extensively demonstrated the feasibility and effectiveness of WF, but only under the strong Single Page Assumption: the network flow extracted by the adversary always belongs to a single page. In other words, the WF classifier will never be asked to classify a network flow corresponding to more than one page, or part of a page. The Single Page Assumption is unrealistic because people often browse with multiple tabs. When this happens, the network flow induced by multiple tabs will overlap, and current WF attacks fail to classify correctly. Yixiao Xu, Tao Wang 0012, Qi Li 0002, Qingyuan Gong, Yang Chen 0001, Yong Jiang 0001 |
ACSAC | 2 |
| 2017 | Walkie-Talkie: An Efficient Defense Against Passive Website Fingerprinting Attacks
Tao Wang 0012, Ian Goldberg 0001 |
USENIX Security Symposium | 1 |
| 2016 | On Realistically Attacking Tor with Website FingerprintingabstractAbstract Website fingerprinting allows a local, passive observer monitoring a web-browsing client’s encrypted channel to determine her web activity. Previous attacks have shown that website fingerprinting could be a threat to anonymity networks such as Tor under laboratory conditions. However, there are significant differences between laboratory conditions and realistic conditions. First, in laboratory tests we collect the training data set together with the testing data set, so the training data set is fresh, but an attacker may not be able to maintain a fresh data set. Second, laboratory packet sequences correspond to a single page each, but for realistic packet sequences the split between pages is not obvious. Third, packet sequences may include background noise from other types of web traffic. These differences adversely affect website fingerprinting under realistic conditions. In this paper, we tackle these three problems to bridge the gap between laboratory and realistic conditions for website fingerprinting. We show that we can maintain a fresh training set with minimal resources. We demonstrate several classification-based techniques that allow us to split full packet sequences effectively into sequences corresponding to a single page each. We describe several new algorithms for tackling background noise. With our techniques, we are able to build the first website fingerprinting system that can operate directly on packet sequences collected in the wild. Tao Wang 0012, Ian Goldberg 0001 |
Proc. Priv. Enhancing Technol. | 1 |
| 2014 | A Systematic Approach to Developing and Evaluating Website Fingerprinting DefensesabstractFingerprinting attacks have emerged as a serious threat against privacy mechanisms, such as SSL, Tor, and encrypting tunnels. Researchers have proposed numerous attacks and defenses, and the Tor project now includes both network- and browser-level defenses against these attacks, but published defenses have high overhead, poor security, or both. Xiang Cai, Rishab Nithyanand, Tao Wang 0012, Rob Johnson 0001, Ian Goldberg 0001 |
CCS | 3 |
| 2014 | Effective Attacks and Provable Defenses for Website Fingerprinting
Tao Wang 0012, Xiang Cai, Rishab Nithyanand, Rob Johnson 0001, Ian Goldberg 0001 |
USENIX Security Symposium | 1 |